Ronin Bridge Hack (2022)
O que é Ronin Bridge Hack (2022)?
Ronin Bridge Hack (2022)A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys.
The Ronin Network bridge was the cross-chain bridge supporting Axie Infinity, the popular play-to-earn game built by Sky Mavis on the Ronin sidechain. On 23 March 2022 attackers withdrew 173,600 ETH and 25.5 million USDC (~US $625 million) from the bridge in two transactions. The bridge required signatures from 5 of 9 validator nodes to authorize withdrawals; investigators found that the attackers had compromised four Sky Mavis-controlled validator keys, plus a fifth controlled by the Axie DAO that Sky Mavis had been temporarily authorized to sign on behalf of months earlier — leaving the bridge with only one effective signer. Compromise was achieved via a spear-phishing PDF sent to a Sky Mavis engineer that delivered a backdoor on the engineer's machine. The U.S. Treasury OFAC and Chainalysis attributed the attack to North Korea's Lazarus Group (APT38). The Ronin incident reshaped Web3 security thinking: bridge designs concentrated trust in small validator sets are catastrophic single-points-of-failure, and even social-engineering-grade attacks on a single engineer can have nine-figure consequences.
● Exemplos
- 01
The March 2022 Ronin attack ($625M) was attributed by U.S. Treasury OFAC to Lazarus Group via a phishing-driven compromise of validator nodes.
- 02
Subsequent bridge designs (Wormhole's Guardian set, LayerZero, Across) cite Ronin as the motivating example for moving away from small custodial validator sets.
● Perguntas frequentes
O que é Ronin Bridge Hack (2022)?
A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys. Pertence à categoria Web3 e blockchain da cibersegurança.
O que significa Ronin Bridge Hack (2022)?
A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys.
Como funciona Ronin Bridge Hack (2022)?
The Ronin Network bridge was the cross-chain bridge supporting Axie Infinity, the popular play-to-earn game built by Sky Mavis on the Ronin sidechain. On 23 March 2022 attackers withdrew 173,600 ETH and 25.5 million USDC (~US $625 million) from the bridge in two transactions. The bridge required signatures from 5 of 9 validator nodes to authorize withdrawals; investigators found that the attackers had compromised four Sky Mavis-controlled validator keys, plus a fifth controlled by the Axie DAO that Sky Mavis had been temporarily authorized to sign on behalf of months earlier — leaving the bridge with only one effective signer. Compromise was achieved via a spear-phishing PDF sent to a Sky Mavis engineer that delivered a backdoor on the engineer's machine. The U.S. Treasury OFAC and Chainalysis attributed the attack to North Korea's Lazarus Group (APT38). The Ronin incident reshaped Web3 security thinking: bridge designs concentrated trust in small validator sets are catastrophic single-points-of-failure, and even social-engineering-grade attacks on a single engineer can have nine-figure consequences.
Como se defender contra Ronin Bridge Hack (2022)?
As defesas contra Ronin Bridge Hack (2022) costumam combinar controles técnicos e práticas operacionais, conforme detalhado na definição acima.
Quais são outros nomes para Ronin Bridge Hack (2022)?
Nomes alternativos comuns: Axie Infinity hack, Sky Mavis Ronin breach.
● Termos relacionados
- web3№ 1379
Wormhole Bridge Hack (2022)
A February 2022 attack on the Wormhole cross-chain bridge between Solana and Ethereum that minted 120,000 wETH worth ~$326 million by exploiting a signature-verification flaw in the bridge's smart contract.
- web3№ 830
Nomad Bridge Hack (2022)
An August 2022 attack on the Nomad cross-chain bridge where a single misconfigured trusted-root value allowed any user to copy-paste an existing withdrawal transaction with a different recipient — a chaotic ~$190 million crowd-drain.
- web3№ 1171
Seguranca de Contratos Inteligentes
Pratica de projetar, revisar e operar programas on-chain para que nao possam ser explorados para roubar fundos, congelar a logica ou violar regras de negocio.
- web3№ 1170
Auditoria de Contratos Inteligentes
Revisao de seguranca independente do codigo-fonte, da configuracao de deploy e do desenho economico de um contrato inteligente antes do lancamento ou de uma atualizacao.
- attacks№ 1191
Spear phishing
Ataque de phishing direcionado e personalizado contra uma pessoa ou organização específica, usando dados pessoais ou profissionais recolhidos previamente.
- web3№ 122
Seguranca em Blockchain
Disciplina que protege livros-razao distribuidos, seus mecanismos de consenso, contratos inteligentes e infraestrutura associada contra comprometimento, fraude e roubo.